MikroTik releases patches for six flaws in RouterOS following active exploitation of vulnerabilities that allow attackers to seize control of routers via SSH, prompting urgent security advisories and increased threat awareness.
MikroTik has issued patches for six flaws in RouterOS, its router operating system, after researchers said two of the bugs could be linked to seize devices over SSH without any prior authentication. CERT Polska said it has seen active attacks against RouterOS systems exposed to the internet, and confirmed that intruders are using the weakness chain to take complete control of routers whose SSH service is reachable from public networks.
The exploit path, which the researchers have nicknamed MikroTrick, affects multiple parts of the firmware rather than a single feature. According to the details released by CERT Polska and reported by CSO, the bugs sit in the SSH server and client, the bandwidth-test service, X.509 certificate handling and the WebFig management interface. MikroTik has advised administrators not to expose SSH directly on internet-facing interfaces and to rely on strong VPN access instead.
The latest disclosure fits a long pattern of abuse against MikroTik hardware. CSO has previously reported on unpatched RouterOS flaws being used continuously by criminal groups, including CVE-2018-14847, which CISA has placed in its catalogue of commonly exploited vulnerabilities. Researchers have also linked compromised MikroTik routers to botnets such as Meris, which were used in major distributed denial-of-service campaigns.
Earlier investigations have shown how widely these devices can be abused once a flaw is exposed. Netlab 360 previously found more than 7,500 compromised MikroTik routers forwarding traffic to attacker-controlled servers, with the affected traffic including FTP, IMAP, POP3, SMTP and SNMP sessions. That history underlines why administrators are being urged to patch quickly and to remove remote management services from public access wherever possible.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





